Autonomous Agent Protocols (MCP & A2A)
5. Autonomous Agent Trust Protocols
Section titled “5. Autonomous Agent Trust Protocols”5.1 Model Context Protocol (MCP) Streamable HTTP
Section titled “5.1 Model Context Protocol (MCP) Streamable HTTP”DID.is inspects MCP tool servers over Streamable HTTP transports across two normative profiles.
5.1.1 Transport Versions
Section titled “5.1.1 Transport Versions”- Current Stateless (
2026-07-28):- Discover:
POST /withMcp-Method: server/discoverandMCP-Protocol-Version: 2026-07-28. - Tools:
POST /withMcp-Method: tools/list(paginated up toMAX_PAGES = 10,MAX_TOOLS = 500). - Client metadata: Carried in
_metacontainingio.modelcontextprotocol/protocolVersionandclientInfo.
- Discover:
- Legacy Session (
2025-11-25):- Handshake:
POST /(initialize) $\to$POST /(notifications/initialized). - Session tracking: Subsequent requests carry
Mcp-Session-Id. - Teardown: Emits
DELETE /to terminate session.
- Handshake:
5.1.2 Tool Fingerprinting
Section titled “5.1.2 Tool Fingerprinting”Every tool exposed by an MCP server is assigned dual cryptographic fingerprints:
- Definition Hash: $$\text{definition_sha256} = \text{hex}(\text{SHA-256}(\text{JCS}(\text{tool_object})))$$
- Schema Hash: $$\text{schema_sha256} = \text{hex}(\text{SHA-256}(\text{JCS}(\text{tool.inputSchema})))$$
- Server Inventory Hash: Sort pairs $[[\text{name}_1, \text{hash}_1], [\text{name}_2, \text{hash}_2], \dots]$ by name, canonicalize with JCS, and compute SHA-256: $$\text{inventory_hash} = \text{hex}(\text{SHA-256}(\text{JCS}(\text{sorted_pairs})))$$
5.1.3 Heuristic vs. Declared Risk Classification
Section titled “5.1.3 Heuristic vs. Declared Risk Classification”DID.is decouples server self-declarations from observed heuristics:
- Declared Class: Extracted from tool annotations (
readOnlyHint,destructiveHint,openWorldHint). - Heuristic Class: Independent lexical analysis of tool name, description, and input schema property tokens against precedence:
$$\text{system_execution} > \text{write} > \text{network_egress} > \text{read_only}$$
system_execution: Matchesexec,shell,bash,cmd,spawn,subprocess,sudo,eval,terminal.write: Matcheswrite,create,update,delete,drop,commit,push,deploy,transfer,pay,purchase,revoke.network_egress: Matchesfetch,http,url,download,upload,webhook,email,crawl,scrape,slack.
- Security Signals:
- Prompt injection heuristics: Scanned for
"ignore previous","system prompt","<important>","private key","api key". - Unicode evasion: Scanned for invisible or bidirectional Unicode (e.g.
U+200B..U+200F,U+202A..U+202E,U+FEFF,U+E0000..U+E007F). - Mismatch alerting: Triggered if
declared == "read_only"but heuristic detectswrite,network_egress, orsystem_execution.
- Prompt injection heuristics: Scanned for
5.2 Linux Foundation A2A Protocol v1.0.0
Section titled “5.2 Linux Foundation A2A Protocol v1.0.0”The Agent-to-Agent (A2A) protocol defines discovery and authentication for autonomous services.
- Discovery:
Fetches
/.well-known/agent-card.json(fallback/.well-known/agent.json), capped atMAX_CARD_BYTES = 512 * 1024(512 KiB). - Interface Binding:
Validates
supportedInterfaces[]against known bindings:JSONRPC,GRPC,HTTP+JSON. - Detached JWS Signature Verification:
- Strips the
signaturesproperty from the agent card. - Canonicalizes the remaining card object with RFC 8785 (JCS).
- Verifies detached JWS signatures over the canonical bytes.
- Resolves signer keys via DID
kid(usingassertionMethod) or HTTPSjkuJWK Set (capped at 128 KiB, validated throughSafeHttpClient).
- Strips the